Hacker News new | ask | show | jobs
by carlosrg 4695 days ago
Exactly. Comparing that javascript with the Chrome situation is just ridiculous. It seems people here are too narrow-minded to understand that even my mother could get a list of all the passwords stored in a computer in 10 seconds.
2 comments

"Even my mother"? So what? Both Firefox and Chrome are, when left on an unlocked user account, completely exposed to the scariest classes of attackers. But Firefox has taken a cosmetic step to minimize its exposure to the least scary class of attackers. Why bother?
Because the 'least scary class of attackers' represent the vast majority of potential attackers. This feature makes it trivial for a user error (not locking your desktop) to leave your passwords immediately visible to anyone that walks by.

Yes, this is cosmetic and anyone with sufficient technical knowledge can still get the passwords without the chrome:settings page, but this feature widens the pool of capable attackers to absolutely everyone.

If you leave your machine unlocked, you have made it trivial for someone to steal your secrets no matter what Chrome does.
Degree of difficulty matters. The technical ability of the attacker matters.

With this feature, it's trivial for absolutely anyone to steal my secrets in seconds.

Without this feature, the time-to-compromise goes up, as does the technical knowledge required. The degree-of-difficulty (which, yes, is still low), goes up.

It is cosmetic, but INTERFACE MATTERS. If you don't want people doing something, don't have a feature that makes it trivially easy.

Hell, if chrome devs really aren't going to do anything at all about this, then a better solution here would be to bring the button to the FRONT of the interface. 'View All Passwords', right beside the 'back' button, navigates you to a raw txt file of websites and passwords. Then, at least, there would be no excuse, no naive assumption that chrome is doing SOMETHING to protect your passwords.

Yes, degree of difficulty matters. We don't disagree on that. It's the fundamental rule of security.

What we disagree on is the specific degree in this case. You think it's significant. I know it's not. Chrome's security design is denominated in thousands of dollars. This is a penny feature, and one with potential liabilities; it could cost more than it benefits.

With the feature, I can explain to my mom, my girlfriend, my sister how to steal passwords from any chrome browser. In a way that they will remember and be able to repeat tomorrow.

Without it, I can't.

That matters.

Can you please explain the potential liabilities for making Chrome work the same way Safari does when attempting to reveal passwords? (I.e., ask for the Keychain password before unmasking.)

To me this would be a great solution and would improve Chrome's user experience. I am unsure why the strong argument against this.

Leaving your machine unlocked for 30 seconds versus 5 minutes is a big difference to some people. Chrome makes password access within the former time limit a more distinct possibility.

Having someone able to casually browse your passwords versus intending to attack your system and breach your trust to get them is a big difference.

Can you not see that Chrome lowers social and emotional barriers to password access by presenting them in this form? That is the concern here.

Your mother knows about chrome:// URLs? Most mundane/non-technical people I know don't know about URLs at all? My mother still types "www.facebook.com" into the Google search bar on google.com.